Skip to content

Security: PeerbitsSolution/audit-logger

Security

SECURITY.md

Security policy

Supported versions

Security fixes are provided for the latest published major version.

Version Supported
1.x Yes
< 1.0 No

Reporting a vulnerability

Do not open a public issue. Use GitHub's private vulnerability reporting for PeerbitsSolution/audit-logger, or email security@peerbits.com. Do not include PHI, credentials, client-identifying information, or production audit records in the report.

Include the affected version, impact, minimal synthetic reproduction, and any known mitigations. Maintainers will acknowledge the report, investigate it, and coordinate disclosure and remediation based on severity.

Security boundaries

This package:

  • does not store PHI or validate whether an opaque ID is semantically de-identified;
  • does not provide production persistence, authorization, encryption, or key management;
  • provides tamper evidence, not tamper prevention or writer authentication;
  • cannot establish HIPAA compliance by itself.

Production deployments must follow the Production Sink Guide and the deploying organization's risk analysis, policies, and legal obligations.

There aren't any published security advisories